Candleread
Crypto and DeFi · Custody and Security

Hot wallets: the convenience and the catch

Define hot wallets (browser extensions, mobile apps) and explain the security trade-offs they carry.

3 min read+25 XPLesson 61 of 79
Start reading

Lesson path

Crypto and DeFi

Custody and Security

Lesson 61 of 7977%
Lesson 61 of 79Crypto and DeFiCustody and Security

Today's tiny win: make one idea click.

Define hot wallets (browser extensions, mobile apps) and explain the security trade-offs they carry.

Learn itSpot itPass the check

What a hot wallet actually is

A hot wallet is any crypto wallet that lives on a device connected to the internet. Your phone app, the browser extension that pops up when a site asks you to 'connect wallet', the wallet inside a desktop client — all hot wallets. The defining trait is online. Online means usable, fast, one-click. Online also means reachable.

Wick holds a small scoop of gas money next to a jar labeled hot wallet, with a note saying only what you could lose, showing a hot wallet is pocket cash, not a vault.Only what you could loseHot walletGas money
Wick saysKeep only what you could lose tomorrow on a hot wallet, like cash in your pocket.

Hot wallets are how almost everyone interacts with crypto day to day. You need a hot wallet to use any decentralized app, swap on a DEX, mint an NFT, or sign into a Web3 site. They're not bad — they're necessary. The mistake is treating them as a vault. A hot wallet is more like the cash in your pocket than the safe at home.

The threats are not abstract. A malicious browser extension can read what you type, including a seed phrase you copy-pasted to set up a wallet. Clipboard malware can replace the address you copied with an attacker's address — you paste, you sign, the funds go to the wrong place. SIM-swap attacks bypass SMS two-factor authentication. Phishing sites mimic real wallet interfaces and ask you to 'sign in' by entering a seed phrase. Every one of these has cost real users real money.

Wick holds a clipboard of hot wallet threats, each with a red X: bad extension, clipboard swap, SIM swap on SMS and fake sign-in page.Hot wallet threatsBad extensionClipboard swapSIM swap on SMSFake sign-in page
Wick saysBad extensions, clipboard swaps, SIM swaps and fake sign-in pages all target hot wallets.

There are defenses worth using. Keep the phone and browser running a hot wallet clean — minimal extensions, no random app installs from links, OS up to date. Use hardware-backed two-factor authentication on any connected exchange or service, not SMS. Read what you're signing before you sign — modern wallets show the contract being called and the tokens being moved. If anything looks unusual, don't sign. Reject costs you nothing; signing the wrong thing can cost you everything in that wallet.

For a $500 trading account, a reputable mobile wallet is enough — segment it so the hot wallet only sees the funds you actively need to move. Don't load your entire long-term stack into a wallet you also use to click through random Discord links.

Wick stands by a traffic light with red lit for unknown contract, yellow for read the pop-up and green for matches your plan, teaching to read before you sign.Unknown contractRead the pop-upMatches your plan
Wick saysIf a signing pop-up shows a contract you don't know, reject it; rejecting costs nothing.

Recap: hot wallets are online, so they're convenient and exposed. Treat them like cash in your pocket — useful, but never your full net worth.

Knowledge check

Answer before moving on.

0 / 2 answered

1. Which of these is NOT a hot wallet?

2. You're about to sign a transaction in your wallet. The pop-up shows a contract address you don't recognize and a token approval. What's the safe move?

Lesson handoff

Pass the check before saving.

Use the knowledge check first. After you pass it, this card turns into the save-and-continue handoff.